Cybercriminals are currently brand-jacking LinkedIn in an attempt to trick end users into clicking on client-side exploits serving links found in the spoofed emails.

According to security researchers from GFI Labs, the spamvertised campaign is redirecting users to the Black Hole web malware exploitation kit, that is ultimately dropping a Cridex malware variant on the infected PCs.

Spamvertised subjects

LinkedIn Invitation from your colleague

LinkedIn Invitation from your co-worker

LinkedIn Reminder from your colleague

LinkedIn Notification

LinkedIn private message

Spamvertised message:

There are a total of 1 messages awaiting your response. Visit your InBox now.